CVE-2025-66215

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE in card-oberthur. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opensc_project:opensc:*:*:*:*:*:*:*:*

History

01 Apr 2026, 17:28

Type Values Removed Values Added
First Time Opensc Project opensc
Opensc Project
CPE cpe:2.3:a:opensc_project:opensc:*:*:*:*:*:*:*:*
References () https://github.com/OpenSC/OpenSC/commit/efd1d479832141bcf705c2f47655ada4d5f92f5d - () https://github.com/OpenSC/OpenSC/commit/efd1d479832141bcf705c2f47655ada4d5f92f5d - Patch
References () https://github.com/OpenSC/OpenSC/pull/3436 - () https://github.com/OpenSC/OpenSC/pull/3436 - Issue Tracking, Patch
References () https://github.com/OpenSC/OpenSC/security/advisories/GHSA-q5fc-cw56-hwp2 - () https://github.com/OpenSC/OpenSC/security/advisories/GHSA-q5fc-cw56-hwp2 - Patch, Vendor Advisory
References () https://github.com/OpenSC/OpenSC/wiki/CVE-2025-66215 - () https://github.com/OpenSC/OpenSC/wiki/CVE-2025-66215 - Vendor Advisory

01 Apr 2026, 14:24

Type Values Removed Values Added
Summary
  • (es) OpenSC es herramientas y middleware de código abierto para tarjetas inteligentes. Antes de la versión 0.27.0, un atacante con acceso físico al ordenador en el momento en que el usuario o el administrador utiliza un token puede causar una escritura de desbordamiento de búfer de pila en card-oberthur. El ataque requiere un dispositivo USB o tarjeta inteligente especialmente diseñado que presentaría al sistema respuestas especialmente diseñadas a las APDU. Este problema ha sido parcheado en la versión 0.27.0.

30 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-30 18:16

Updated : 2026-04-01 17:28


NVD link : CVE-2025-66215

Mitre link : CVE-2025-66215

CVE.ORG link : CVE-2025-66215


JSON object : View

Products Affected

opensc_project

  • opensc
CWE
CWE-121

Stack-based Buffer Overflow